Description
Simmer is a small community recipe box where home cooks publish recipes, leave comments, and keep a profile. It looks friendly and unremarkable — which is exactly the point. Somewhere in this tidy little app is a clean path from anonymous visitor to full control of the server, and your job is to read the code, find it, and prove it with a script.
Difficulty vs OSWE: Well below the OSWE exam. Simmer is a warm-up — the gentlest introduction to white-box web hacking and to writing your first unauthenticated-to-RCE exploit end to end. If you’re new to source review, start here.
Setup
- Download the
SimmerOVA from Theosec Labs. - Import into VirtualBox — File → Import Appliance, select the
.ova, and import. Make sure the VM and your host can reach each other both ways (you’ll need that for the reverse shell). - Start the VM. At the console login, sign in and find its IP:
- Username:
student· Password:simmer - Run
ifconfig(orip a) and note the address (e.g.192.168.56.x).
- Username:
- Open the in-browser debugger. Browse to
http://<vm-ip>:8080(code-server). Password:simmer— there is no username.- Open Folder → choose the folder named
simmer. - Click the Run and Debug icon in the left sidebar.
- Click the green ▶ Start Debugging button to launch a debug instance of the app.
- Set breakpoints and step through the code as you investigate.
- Open Folder → choose the folder named
- Read the source to find the vulnerabilities.
- Write your exploit. The target app is at
http://<vm-ip>/(port 80). Write a script (Python recommended) that automates the whole chain — unauthenticated → admin → remote code execution — and, at the RCE step, fires a reverse shell back to anc -lvnp <port>listener on your machine. Running the script should catch you a shell as the web server user. - Capture
local.txtandproof.txt.